CVE-2021-2019
Published on: 01/20/2021 12:00:00 AM UTC
Last Modified on: 01/04/2022 05:27:00 PM UTC
Certain versions of Fedora from Fedoraproject contain the following vulnerability:
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
- CVE-2021-2019 has been assigned by
[email protected] to track the vulnerability - currently rated as LOW severity.
- Affected Vendor/Software:
Oracle Corporation - MySQL Server version = 8.0.19 and prior
CVSS3 Score: 2.7 - LOW
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVSS2 Score: 4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
MySQL: Multiple vulnerabilities (GLSA 202105-27) — Gentoo security | security.gentoo.org text/html |
![]() |
[SECURITY] Fedora 32 Update: mysql-connector-odbc-8.0.23-1.fc32 - package-announce - Fedora Mailing-Lists | Mailing List Third Party Advisory lists.fedoraproject.org text/html |
![]() |
January 2021 MySQL Vulnerabilities in NetApp Products | NetApp Product Security | Third Party Advisory security.netapp.com text/html |
![]() |
[SECURITY] Fedora 33 Update: community-mysql-8.0.23-1.fc33 - package-announce - Fedora Mailing-Lists | Mailing List Third Party Advisory lists.fedoraproject.org text/html |
![]() |
Oracle Critical Patch Update Advisory - January 2021 | Vendor Advisory www.oracle.com text/html |
![]() |
Related QID Numbers
- 690266 Free Berkeley Software Distribution (FreeBSD) Security Update for mysql (31344707-5d87-11eb-929d-d4c9ef517024)
- 710088 Gentoo Linux MySQL Multiple vulnerabilities (GLSA 202105-27)
- 940103 AlmaLinux Security Update for mysql:8.0 (ALSA-2020:3732)
- 960190 Rocky Linux Security Update for mysql:8.0 (RLSA-2020:3732)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Fedoraproject | Fedora | 32 | All | All | All |
Operating System | Fedoraproject | Fedora | 33 | All | All | All |
Operating System | Fedoraproject | Fedora | 32 | All | All | All |
Operating System | Fedoraproject | Fedora | 33 | All | All | All |
Application | Netapp | Oncommand Insight | - | All | All | All |
Application | Netapp | Oncommand Insight | - | All | All | All |
Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
Application | Netapp | Snapcenter | - | All | All | All |
Application | Netapp | Snapcenter | - | All | All | All |
Application | Oracle | Mysql | All | All | All | All |
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|